V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2014-8500
DEB
Medium

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attack…

CVSS
5.0
Medium
EPSS
0.48
p97
Published
2014-01-01
Updated
2014-01-01
Description

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

Tags · CWE
CWE-399
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Bind
CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.482 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
bindTracked
bindTracked
bindTracked
bindTracked
bindTracked
bindTracked
bind-develTracked
bind-docTracked
bind-utilsTracked
bind9Tracked
bind9Tracked
bind9Tracked
bind97Tracked
libbindTracked
libisc-exportTracked
libisc-export-develTracked
lwresdTracked
bind*Tracked
Source databases
DEB
CVE
RED
UBU